Home > Midmarket CIO Tips > Data centers and infrastructure for the midmarket > Secure VoIP in simple steps
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

DATA CENTERS AND INFRASTRUCTURE FOR THE MIDMARKET

Secure VoIP in simple steps


Joel Dubin, CISSP, Contributor
11.20.2006
Rating: -3.63- (out of 5)


Technology news and tips for midmarket CIOs
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Securing Voice over IP (VoIP) doesn't have to be a challenge for small and medium-sized businesses (SMBs). VoIP is basically a phone call over the Internet. It offers the same promises -- and pitfalls -- as the Internet. The promises are cheap and easy communication over a readily available and easy-to-use public network -- the Internet. The pitfalls are the same security weaknesses of that network, which wasn't originally designed for security -- or phone calls, for that matter.

But it's not as scary as it seems for cash-strapped SMBs with limited IT staffs. Most of the tuning required to secure VoIP involves the same efforts as hardening Internet and Web connections your company probably already has in place. And most of that work can be handled by your existing network staff, even without a dedicated information security department.

Even if your SMB doesn't host its own Web site or Internet service, like a larger enterprise, it still has connections to the Internet through conventional routers. Handling VoIP for them should be a snap.

Security comes first

Before delving into the four best practices for securing VoIP and how to apply them to SMBs, be aware of the overall security issues around VoIP.

There are three major security concerns around VoIP, and they're the same security issues as those for IP traffic, in general. The three issues are:

VoIP can also serve as an entry point into your company, just like any other Internet connection, for viruses, spyware and malware. But this isn't a specific problem of VoIP. Denial-of-service (DoS) attacks are also possible via VoIP but, again, this is a general IP protocol issue and not just a VoIP concern.

IP traffic isn't authenticated. It moves freely over the Internet and can come from anywhere. This is a problem inherent in the TCP/IP protoco


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Data centers and infrastructure for the midmarket
Pricing out Windows Server 2008 for virtualization cost efficiency
Data center strategy starts with the business
Desktop and application virtualization: Lessons learned
FAQ: What is unified communications, and why would I want it?
Virtualization technology creates hosts of problems for midmarket IT shops
Virtual servers key to consolidated data center
Fixed-mobile convergence saves firms costly mobile phone charges
Virtualization the center of county's 'disaster avoidance' plan
Five tips that could change your data center
Converged networks a risky business

VoIP and unified messaging for the midmarket
Midmarket data center management guides: Tips and best practices
FAQ: What is unified communications, and why would I want it?
Mobile unified communications options for the midmarket
Fixed-mobile convergence saves firms costly mobile phone charges
Unified communications plans should tap CIO
CIOs grapple with tying Wi-Fi, VoIP into unified communications plan
Unified communications: Savvy business move or security meltdown?
Unified communications: Securing access to OCS
Unified communications security: How safe is it?
CIO Joseph Edward: In-house app ties parishes together

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


l. For VoIP, it means a malicious user could fake, or spoof, your company's IP address and appear on the caller ID of an unsuspecting customer. This tactic is known as VoIP phishing, which, like its email counterpart, is meant to entice customers to give up confidential account information over the phone to thieves posing as your company employees.

IP traffic moves in the clear by default. It can be easily picked up by conventional packet sniffers like Wireshark (formerly Ethereal), dsniff, Ettercap and their ilk. Any conversations on your new shiny VoIP phones can be eavesdropped by sniffing unencrypted traffic traveling over the Internet. Unlike regular phone lines, which require some effort to tap through the phone company, VoIP can potentially expose your SMB to the whole world just by being on the Internet.

And, just as spam is delivered via email, junk voicemail messages can be pumped into your company through VoIP, clogging your SMB's phones with SPIT. This is in addition to a DoS attack against your company, just like any other from the Internet, through your VoIP connection.

So, what's an SMB to do to protect itself from the dangers of VoIP? Here are four suggestions:

Like the rest of your network servers, baseline security controls should be in place for your VoIP system. Here's how:

Implementing VoIP is not as scary, or as much of a burden, as it seems. Most of the tasks for securing VoIP can be handled by your existing IT staff, since it is already integrated into your network.

Joel Dubin, CISSP, is an independent computer security consultant in Chicago. He is a Microsoft MVP in security, specializing in Web and application security, and the author of The Little Black Book of Computer Security available from Amazon. You can visit his blog, The IT Security Guy, at www.theitsecurityguy.com.

Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Mid-market CIO Business Solutions on Data Integrity, Unified Communications, and Virtualization
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts